A critical vulnerability in The Sandbox's cross-chain infrastructure was promptly fixed. An attacker, exploiting a flaw in the bridge between the Base and BNB Smart Chain networks, carried out unauthorized minting of SAND tokens in both networks without corresponding backing.
Analysis of the incident shows that the attack was carried out through the approveAndCall function: the hacker intercepted LayerZero delegate rights, allowing them to manipulate the bridge process. The scale of the damage was minimal—less than 0.01% of the total SAND supply. Crucially, tokens on the Ethereum (ETH) and Polygon (POL) networks remained untouched, and user wallets were not compromised.
According to monitoring data, approximately $49 million worth of fake SAND was minted during the attack across more than 400 transactions. The Sandbox team immediately disabled the bridges between Base and BSC, blocking the movement and recovery of the generated tokens. SAND locked on Ethereum, which serves as backing for all bridges, remained safe.
Reaction from exchanges and the ecosystem
Korean crypto exchanges responded quickly to the incident. Bithumb suspended SAND deposits and withdrawals at 05:11 Moscow time, and Upbit followed suit a minute later. Both platforms cited suspicions of a security breach and local legislation on protecting virtual asset owners' rights. Notably, Upbit even closed operations for the SAND version on the Ethereum network, although that network was not affected by the attack.
The developers warned holders against buying, selling, or trading SAND in the affected networks, as token liquidity there has been disrupted. A network snapshot from before the attack is being prepared for payouts to affected liquidity providers. The team promises to publish a full report on the incident later.
This incident is another link in an alarming chain: according to DefiLlama, there have been 17 hacks in the past month, and cross-chain bridges once again proved to be the industry's weak point. My conclusion: as long as cross-chain protocols rely on complex delegate mechanisms like LayerZero, such targeted attacks will recur. Investors should be more cautious with assets on bridges and diversify risks across networks.